IOS 10.2.1 正式版推出 - iOS

Jack avatar
By Jack
at 2017-01-24T05:30

Table of Contents

https://support.apple.com/en-us/HT207482

This document describes the security content of iOS 10.2.1.

iOS 10.2.1

Released January 23, 2017


Auto Unlock 自動解鎖問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:當Apple watch離開你的手時仍然會自動解鎖
Impact: Auto Unlock may unlock when Apple Watch is off the user's wrist

Description: A logic issue was addressed through improved state management.
CVE-2017-2352: Ashley Fernandez of raptAware Pty Ltd


Contacts 聯絡人問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意的聯絡人資料卡可能造成程式中止
Impact: Processing a maliciously crafted contact card may lead to unexpected
application termination

Description: An input validation issue existed in the parsing of contact
cards. This issue was addressed through improved input validation.
CVE-2017-2368: Vincent Desmurs (vincedes3)


Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges

Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2017-2370: Ian Beer of Google Project Zero


Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges

Description: A use after free issue was addressed through improved memory
management.
CVE-2017-2360: Ian Beer of Google Project Zero


libarchive 資料庫封存問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:打開惡意產生的封包可能導致程式碼任意執行
Impact: Unpacking a maliciously crafted archive may lead to arbitrary code
execution

Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2016-8687: Agostino Sarubbo of Gentoo


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin

Description: A prototype access issue was addressed through improved
exception handling.
CVE-2017-2350: Gareth Heyes of Portswigger Web Security


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution

Description: Multiple memory corruption issues were addressed through
improved memory handling.
CVE-2017-2354: Neymar of Tencent's Xuanwu Lab (tencent.com) working with
Trend Micro's Zero Day Initiative
CVE-2017-2362: Ivan Fratric of Google Project Zero
CVE-2017-2373: Ivan Fratric of Google Project Zero


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution

Description: A memory initialization issue was addressed through improved
memory handling.
CVE-2017-2355: Team Pangu and lokihardt at PwnFest 2016


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution

Description: Multiple memory corruption issues were addressed through
improved input validation.
CVE-2017-2356: Team Pangu and lokihardt at PwnFest 2016
CVE-2017-2369: Ivan Fratric of Google Project Zero
CVE-2017-2366: Kai Kang of Tencent's Xuanwu Lab (tencent.com)


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin

Description: A validation issue existed in the handling of page loading. This
issue was addressed through improved logic.
CVE-2017-2363: lokihardt of Google Project Zero
CVE-2017-2364: lokihardt of Google Project Zero


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意網站可以打開彈出式視窗
Impact: A malicious website can open popups

Description: An issue existed in the handling of blocking popups. This was
addressed through improved input validation.
CVE-2017-2371: lokihardt of Google Project Zero


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin

Description: A validation issue existed in the handling of variable handling.
This issue was addressed through improved validation.
CVE-2017-2365: lokihardt of Google Project Zero


WiFi 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:有啟動鎖定的裝置可以在操作下短暫的顯示首頁
Impact: An activation-locked device can be manipulated to briefly present the
home screen

Description: An issue existed with handling user input that caused a device
to present the home screen even when activation locked. This was addressed
through improved input validation.
CVE-2017-2351: Sriram (@Sri_Hxor) of Primefort Pvt. Ltd., Hemanth Joseph

--
Tags: iOS

All Comments

Kelly avatar
By Kelly
at 2017-01-28T01:26
TL;DR
Edith avatar
By Edith
at 2017-01-31T02:24
不要上來丟臉了好嗎 你懂英文嗎
Steve avatar
By Steve
at 2017-02-03T11:02
我英文素質低落
Isabella avatar
By Isabella
at 2017-02-06T11:05
可以桶他嗎?
Edith avatar
By Edith
at 2017-02-09T13:20
貼這幹嘛
Adele avatar
By Adele
at 2017-02-13T15:05
iOS 10.2.1 的更新內容啊......
Franklin avatar
By Franklin
at 2017-02-18T10:29
貼上來沒翻譯沒解釋 洗文喔
Franklin avatar
By Franklin
at 2017-02-19T12:46
這個版是怎麼回事......
Quanna avatar
By Quanna
at 2017-02-22T11:16
複製貼上誰都會,內文完全沒有個人意見、看法或說明見
Barb Cronin avatar
By Barb Cronin
at 2017-02-26T03:36
板規6
Frederic avatar
By Frederic
at 2017-02-26T07:03
.
Tracy avatar
By Tracy
at 2017-03-02T09:33
板龜6c
Iris avatar
By Iris
at 2017-03-02T18:28
都用這麼久的ptt了,難道不知道不行複製貼上嗎?
Suhail Hany avatar
By Suhail Hany
at 2017-03-05T02:02
Oliver avatar
By Oliver
at 2017-03-06T22:34
噓你才怎麼了 發文不看版規
Oliver avatar
By Oliver
at 2017-03-08T20:25
快推不然以為我們不懂英文
Kumar avatar
By Kumar
at 2017-03-13T06:55
喔好棒棒喔你懂英文好厲害
Linda avatar
By Linda
at 2017-03-16T13:15
我竟然看得懂......(噗~~~)
Rosalind avatar
By Rosalind
at 2017-03-21T01:40
Ctrl C + V 這樣也好意思一篇?
Andrew avatar
By Andrew
at 2017-03-21T13:10
所以鬧鐘修好了沒?(x
Elizabeth avatar
By Elizabeth
at 2017-03-25T00:07
呃...
Elma avatar
By Elma
at 2017-03-27T05:31
複製貼上的被噓 反觀只貼張截圖就沒問題 廠廠
Noah avatar
By Noah
at 2017-03-29T04:47
我才想問你是怎麼回事咧....
Skylar Davis avatar
By Skylar Davis
at 2017-04-01T13:20
所以勿擾模式修好了沒?
Hedwig avatar
By Hedwig
at 2017-04-02T19:18
什麼叫他媽的驚喜
Daniel avatar
By Daniel
at 2017-04-04T23:35
87
Anonymous avatar
By Anonymous
at 2017-04-06T16:28
欺負我沒讀書喔~ 奇怪捏
Carol avatar
By Carol
at 2017-04-08T07:06
推推
Andy avatar
By Andy
at 2017-04-09T17:34
好啦幫搬運工補個血
Bennie avatar
By Bennie
at 2017-04-11T19:37
好可憐 幫你QQ 果粉不意外
Skylar DavisLinda avatar
By Skylar DavisLinda
at 2017-04-15T11:06
你貼這樣我直接去蘋果不是更快
Carol avatar
By Carol
at 2017-04-16T08:22
我傻眼XD
Blanche avatar
By Blanche
at 2017-04-17T13:48
跟上一篇一樣半斤八兩,反正這邊根本沒版主,貼什麼有差嗎
Isabella avatar
By Isabella
at 2017-04-19T00:52
我覺得有東西看不用去找,不錯啊
Madame avatar
By Madame
at 2017-04-22T06:40
為什麼要噓?
Hardy avatar
By Hardy
at 2017-04-27T04:41
第一篇是情報,第二篇是洗文
Brianna avatar
By Brianna
at 2017-04-29T10:02
這個版素質真的越來越差了
Hedy avatar
By Hedy
at 2017-04-30T19:13
這篇看似洗文章 其實重要性不亞於更新的情報
Gilbert avatar
By Gilbert
at 2017-05-03T11:51
個人認為安全性更新非常重要 必須像有原po這樣的好人
跟大家分享
Agnes avatar
By Agnes
at 2017-05-06T21:33
這篇至少把連結貼出來 情報量比上一篇多太多了
Elizabeth avatar
By Elizabeth
at 2017-05-08T19:46
而且這次的安全性更新本來就是10.2.1的核心
Caroline avatar
By Caroline
at 2017-05-09T16:47
這個板的板主真的好好當喔
Todd Johnson avatar
By Todd Johnson
at 2017-05-11T08:10
.
Yedda avatar
By Yedda
at 2017-05-13T17:35
推個 補血
Callum avatar
By Callum
at 2017-05-13T20:17
自己能力不好,不能去加強嗎,拿別人用好的資料來看,
不就代表自己懶得找懶得看,比別人貼一張好多了吧
Yuri avatar
By Yuri
at 2017-05-17T10:41
推推
Tracy avatar
By Tracy
at 2017-05-20T16:02
原PO辛苦啦,這篇比前一篇來的實用
Daniel avatar
By Daniel
at 2017-05-23T12:45
前面的推文是什麼情形..
Bethany avatar
By Bethany
at 2017-05-24T22:36
推 很有用的情報文
Zora avatar
By Zora
at 2017-05-26T10:48
本來是原文純複製貼上
Emily avatar
By Emily
at 2017-05-28T00:02
前面想帶風向?
Una avatar
By Una
at 2017-05-30T14:58
我莫名奇妙被噓,明明這是比較重要的資訊....
Agnes avatar
By Agnes
at 2017-06-02T05:50
推回來,明明前面那篇才沒用,這篇很多資訊。
Hamiltion avatar
By Hamiltion
at 2017-06-06T02:32
幫推
Kristin avatar
By Kristin
at 2017-06-09T08:24
幫推 有翻譯了
Dinah avatar
By Dinah
at 2017-06-10T19:52
上面是在噓什麼?
Steve avatar
By Steve
at 2017-06-12T15:33
謝謝分享
John avatar
By John
at 2017-06-14T12:15
隨便都比一堆廢文好
Rachel avatar
By Rachel
at 2017-06-16T19:47
推補翻譯
Kumar avatar
By Kumar
at 2017-06-18T21:16
Jake avatar
By Jake
at 2017-06-18T22:52
推翻譯
Zanna avatar
By Zanna
at 2017-06-23T10:59
Audriana avatar
By Audriana
at 2017-06-25T01:53
前面那篇什麼都沒提到 這篇內容都有 有啥好虛..
Barb Cronin avatar
By Barb Cronin
at 2017-06-28T07:13
Steve avatar
By Steve
at 2017-07-01T10:15
推好心翻譯
James avatar
By James
at 2017-07-04T10:18
噓的人是因爲一開始沒翻譯,看不懂才噓的吧
Olga avatar
By Olga
at 2017-07-06T14:37
看了噓的幾樓,真是笑死我了,原來腦袋可以這樣用
Callum avatar
By Callum
at 2017-07-08T21:57
原po一開始只有將英文全部貼上,翻譯是後來才加的
Doris avatar
By Doris
at 2017-07-08T22:57
推推
Franklin avatar
By Franklin
at 2017-07-10T01:47
一開始就算只有英文 至少有付官方連結
我想不管怎樣都比截圖好
Susan avatar
By Susan
at 2017-07-14T13:27
語言不合
Thomas avatar
By Thomas
at 2017-07-18T22:45
Sandy avatar
By Sandy
at 2017-07-22T20:06
再推一次 前面噓的真的很有趣
Barb Cronin avatar
By Barb Cronin
at 2017-07-27T11:37
Connor avatar
By Connor
at 2017-07-28T19:59
補血。上面不知道在噓什麼
Lauren avatar
By Lauren
at 2017-07-31T11:48
幫補血
Hazel avatar
By Hazel
at 2017-08-04T09:19
幫補血,原PO別介意,就是有一堆沒知識的秀下限
Candice avatar
By Candice
at 2017-08-05T02:43
Jake avatar
By Jake
at 2017-08-08T22:34
?噓啥
Xanthe avatar
By Xanthe
at 2017-08-13T01:19
Ursula avatar
By Ursula
at 2017-08-14T15:36
補血
Mary avatar
By Mary
at 2017-08-15T17:10
辛苦原PO。
Madame avatar
By Madame
at 2017-08-19T15:34
推 前面的噓文很有事
Rachel avatar
By Rachel
at 2017-08-21T22:57
Rosalind avatar
By Rosalind
at 2017-08-24T09:09
幫補一發
Rachel avatar
By Rachel
at 2017-08-24T18:44
補血
Elvira avatar
By Elvira
at 2017-08-26T13:24
Lily avatar
By Lily
at 2017-08-27T11:55
Suhail Hany avatar
By Suhail Hany
at 2017-08-30T16:07
前面的還好嗎...?這明明很有用啊
Ethan avatar
By Ethan
at 2017-09-04T01:16
一堆玻璃心看不懂亂噓,上一篇怎不噓?助推一個
Lauren avatar
By Lauren
at 2017-09-07T01:25
怪了 國民教育沒教英文嗎?
Lauren avatar
By Lauren
at 2017-09-08T08:20
補血
Elma avatar
By Elma
at 2017-09-10T13:18
前面都玻璃心喔 幫補
Zanna avatar
By Zanna
at 2017-09-11T09:37
補血
John avatar
By John
at 2017-09-14T06:29
﴿
Oscar avatar
By Oscar
at 2017-09-14T20:43
推推
Irma avatar
By Irma
at 2017-09-18T23:35
補血 推
Madame avatar
By Madame
at 2017-09-23T09:52
前面的噓文有什麼事
Blanche avatar
By Blanche
at 2017-09-27T06:16
第一篇那樣才誇張吧
Carol avatar
By Carol
at 2017-09-28T23:10
從古至今語言是造成戰爭的重要關鍵XD
Kyle avatar
By Kyle
at 2017-09-30T17:40
笑看那些英文不好亂炮的
Adele avatar
By Adele
at 2017-10-01T10:22
前面那些人亂噓在秀下限?自己看不懂就亂噓別人廠廠
Anonymous avatar
By Anonymous
at 2017-10-03T11:06
補推
Erin avatar
By Erin
at 2017-10-07T18:57
覺得很有幫助阿
Erin avatar
By Erin
at 2017-10-08T21:12
OuO 好兇
Odelette avatar
By Odelette
at 2017-10-09T22:10
噓文的人,你們還好嗎?
Odelette avatar
By Odelette
at 2017-10-10T12:28
滿好的
Caitlin avatar
By Caitlin
at 2017-10-11T20:20
這篇充實多了,感謝原po分享
Carolina Franco avatar
By Carolina Franco
at 2017-10-12T18:52
因為前面的看不懂英文 哈哈
Ethan avatar
By Ethan
at 2017-10-14T14:26
一堆看不懂英文在悲憤噓文
Eartha avatar
By Eartha
at 2017-10-19T10:55
蠻好的文啊
Elizabeth avatar
By Elizabeth
at 2017-10-19T18:36
英文都看不懂,一定是9.2

Apple Watch錶面天氣顯示

Olive avatar
By Olive
at 2017-01-24T04:04
------------------------------------------------------------------------------ 我確定問問題前我有爬過文、查閱過精華區與置底,我真的找不到我問題的解答。 我保證我的問題和盜版沒有任何關係,若以上有虛假,版主可逕行處分 發問請附上iO ...

IOS 10.2.1 正式版推出

Noah avatar
By Noah
at 2017-01-24T03:03
如題 已推出最新版10.2.1 徵求白老鼠GO~ http://i.imgur.com/of9fxyC.jpg - ...

iphone6/6s 皮革保護殼通用問題

Elma avatar
By Elma
at 2017-01-24T00:55
爸爸在尾牙的時候抽到6S 媽媽手機比較舊就給她用了 想說幫媽媽買個好一點的保護殼 看到wetherby這個牌子 這款感覺蠻適合媽媽的 http://i.imgur.com/epGfTpk.jpg 準備要付款的時候發現官網只有寫適合iphone 6 一直以為6和6S殼都通用 Google一下發現6S稍微 ...

洛克人

Dinah avatar
By Dinah
at 2017-01-24T00:44
最近發現上架了元祖洛克人1-6 唯獨沒有7 好像元祖復刻常缺7 覺得可惜 最好玩的一款阿 有卦嗎? x也是 出這麼久也常在前100 但就是不出x2....... 有沒有卡普空在想啥的卦? -- V6 慶祝出道20週年精選輯「SUPER Very 6est」好評熱賣中 V6 are 20th Ce ...

iphone6換電池,卻拿不回舊電池!

Genevieve avatar
By Genevieve
at 2017-01-24T00:34
小弟正巧前1/9去五權西路換了IPHONE 6電池 優點: 電池容量冒似比原廠的還大1900》1751 目前循環11次,電池沒異常。 更換迅速,約5~10分鐘。 缺點: 一開始說電池1500,網路1200不是你們,我傻眼時才又說打卡8折1200。 拿進去換,施作不透明。 舊電池沒還我做紀念。 想去換 ...